CVE Database
/

CVE-2010-4700

Back to search

CVE-2010-4700

Published: Jan 18, 2011

Modified: Aug 7, 2024

PUBLISHED

Description

The set_magic_quotes_runtime function in PHP 5.3.2 and 5.3.3, when the MySQLi extension is used, does not properly interact with use of the mysqli_fetch_assoc function, which might make it easier for context-dependent attackers to conduct SQL injection attacks via crafted input that had been properly handled in earlier PHP versions.

VendorProductVersions

n/a

n/a

affected
n/a

References

oval:org.mitre.oval:def:12620
vdb-entry
signature
x_refsource_OVAL
46056
vdb-entry
x_refsource_BID
http://bugs.php.net/52221
x_refsource_CONFIRM

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now